Lucene search

K
redhatRedHatRHSA-2013:1282
HistorySep 24, 2013 - 12:00 a.m.

(RHSA-2013:1282) Important: rtkit security update

2013-09-2400:00:00
access.redhat.com
34

EPSS

0

Percentile

5.1%

RealtimeKit is a D-Bus system service that changes the scheduling policy of
user processes/threads to SCHED_RR (that is, realtime scheduling mode) on
request. It is intended to be used as a secure mechanism to allow real-time
scheduling to be used by normal user processes.

It was found that RealtimeKit communicated with PolicyKit for authorization
using a D-Bus API that is vulnerable to a race condition. This could have
led to intended PolicyKit authorizations being bypassed. This update
modifies RealtimeKit to communicate with PolicyKit via a different API that
is not vulnerable to the race condition. (CVE-2013-4326)

All rtkit users are advised to upgrade to this updated package, which
contains a backported patch to correct this issue.